Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Denial of Service via Quadratic Complexity in kjd/idna
Vulnerability Description
A vulnerability was identified in the kjd/idna library, specifically within the `idna.encode()` function, affecting version 3.6. The issue arises from the function's handling of crafted input strings, which can lead to quadratic complexity and consequently, a denial of service condition. This vulnerability is triggered by a crafted input that causes the `idna.encode()` function to process the input with considerable computational load, significantly increasing the processing time in a quadratic manner relative to the input size.
CVSS Information
N/A
Vulnerability Type
CWE-1333
Vulnerability Title
idna 安全漏洞
Vulnerability Description
idna是国际化域名 (IDNA) 协议。 idna 存在安全漏洞,该漏洞源于通过资源消耗会导致潜在的拒绝服务(DoS)。
CVSS Information
N/A
Vulnerability Type
N/A